WhatsApp on August 25, 2026 replaced the six-digit PIN behind its two-step verification feature with a full alphanumeric password, added caller context for unknown numbers on Android, and disclosed that more than one billion accounts have set up a passkey.
The announcement arrived through the Meta Newsroom under the WhatsApp category, filed against three tags: Data and Privacy, Product News, and WhatsApp. It carries no byline, no named spokesperson, and no rollout schedule. What it carries instead is a change to the credential layer of a messaging service that now doubles as a paid media surface, a customer service channel, and the subject of an active European antitrust remedy.
Three changes were described. Each is small on its own. Together they mark a shift in where WhatsApp places the burden of account integrity, and they land at a moment when account takeover has become an operational problem for the advertising industry rather than a consumer inconvenience.
The PIN becomes a password
Two-step verification on WhatsApp exists to defeat a specific attack: an adversary who has obtained the one-time passcode sent during registration, whether through SIM swap, social engineering, or interception. The feature adds a second secret that the attacker does not hold.
Until the August 25 announcement, that second secret was a six-digit numeric PIN. According to WhatsApp, the company has upgraded it to a full password that is longer, alphanumeric, and capable of containing special characters. The stated purpose is to make the credential harder to guess.
The arithmetic behind that decision is not stated in the announcement, but it is not obscure. A six-digit numeric PIN has one million possible values. A password drawn from mixed-case letters, digits, and punctuation expands that space by orders of magnitude per additional character. Against an attacker who has already cleared the one-time passcode hurdle and is guessing at the second factor, the difference between the two formats is the difference between a search that terminates and one that does not.
What the announcement does not address is migration. There is no statement on whether existing six-digit PINs remain valid, whether users are prompted to upgrade, whether a deadline applies, or whether the change reaches all markets simultaneously. Accounts already carrying a PIN are left in an undefined state by the text as published.
Caller context lands on Android first
The second change concerns inbound calls from numbers not saved in a user's contacts. On Android, WhatsApp now surfaces additional information about the caller before the call is answered: whether the number originates in a different country, and whether the caller shares any groups with the recipient.
Both signals are inferences drawn from metadata rather than message content. Neither requires WhatsApp to inspect the encrypted payload of a conversation, which is consistent with the architecture the company describes. According to WhatsApp, conversations belong only to the participants, and end-to-end encryption by default is the reason the company frames account security as a separate layer of work.
The rationale offered is behavioural. According to WhatsApp, "Scammers rely on urgency," and the added context is intended to slow the decision to answer.
iOS is not mentioned. The announcement specifies Android and stops there, with no parity date and no explanation for the platform split. That asymmetry has precedent in recent WhatsApp releases, several of which have shipped without a market sequence or a distinction between the European Region and other territories.
Passkeys reach one billion accounts
The third disclosure is the only one carrying a number. According to WhatsApp, more than one billion people have set up a passkey, a credential that allows sign-in through a fingerprint, a face scan, or a device screen lock rather than a code or PIN. The company describes it as the fastest and most secure way to complete verification.
Alongside the figure, WhatsApp added a capability: accounts can now hold more than one passkey, which matters for people running both Android and iOS devices. The setup path is Settings, then Account, then Passkeys.
One billion is a substantial share of a user base that stood at three billion monthly active users as of May 2025, the figure cited in Meta's own regulatory materials when WhatsApp opened third-party messaging in Europe under the Digital Markets Act. It is also a figure without a stated baseline. The announcement gives no prior total, no growth rate, and no time window, so the adoption curve cannot be reconstructed from the text.
The credential itself is not new to WhatsApp, and passkeys are not new to Meta's competitors. What has changed over the past eighteen months is the migration of the same mechanism from consumer login into advertising infrastructure.
The same credential now gates ad accounts
Passkey adoption on a messaging app would be a consumer story if the advertising platforms had not made the identical move on their own account systems.
Google Ads began requiring passkeys for sensitive account actions from July 15, 2026, covering account linking updates and user access changes specifically. The requirement surfaced at the developer layer through a boolean field named passkey_enabled in Google Ads API v24.1, released May 13, 2026, allowing integrations to check enrolment state before attempting a sensitive operation. A further deadline followed: from August 5, 2026, generating new OAuth 2.0 refresh tokens through the Google Ads API authentication workflow requires a passkey, with a seven-day device trust period that agencies rotating staff onto accounts have flagged as an operational trap.
The structural consequence for agencies is that passkeys cannot be shared. Organisations running shared credentials across a team must assign individual accounts to each person performing sensitive operations, a change that reaches into how account access is administered rather than merely how it is authenticated.
WhatsApp's consumer-side figure and the ad platforms' enforcement deadlines are separate programmes with separate timelines. They point the same direction. The password, as a transferable secret, is being retired across both sides of the platform economy, and the replacement is bound to a physical device.
Why a security post matters to media buyers
WhatsApp is no longer a purely organic channel. Meta began placing advertisements on WhatsApp Status on June 16, 2025, targeting the roughly 1.5 billion people who open the Updates tab daily and drawing targeting signals from connected Instagram and Facebook accounts. Meta's third Digital Markets Act compliance report, filed March 6, 2026, confirmed that Channels and Status advertising was being prepared for the European Union. Advertisers gained a WhatsApp filter in the Meta Ads Library in December 2025, and Marketing API v26.0 expanded the placement further, requiring third-party callers to include a wamo_whatsapp_identity_spec field in creatives intended for Status delivery.
The business layer moved in parallel. Meta launched Meta Business Agent globally on June 3, 2026, putting AI customer service across WhatsApp, Messenger, and Instagram, and the WhatsApp Business Calling API arrived on July 1, 2025 to fold voice into existing message threads. Onboarding for Click-to-WhatsApp campaigns was consolidated in embedded signup v4, which sets an October 15, 2026 deprecation deadline for the two prior versions.
Every one of those commercial surfaces sits on top of a consumer account. A compromised account is a compromised endpoint for a conversational campaign, a hijacked identity in a Click-to-WhatsApp funnel, and an attack surface for the scam operations Meta has spent two years trying to remove from its own inventory.
The fraud economy the changes sit against
The commercial context for account hardening at Meta is unusually well documented, largely because much of it has been documented against the company's wishes.
Internal documents reviewed by Reuters in November 2025 indicated Meta projected roughly 10% of its 2024 revenue from advertisements for scams and banned goods, and estimated that its platforms showed users around 15 billion higher-risk scam advertisements a day. The Consumer Federation of America filed a class action in the Superior Court of the District of Columbia on April 21, 2026, citing a 2023 internal document showing approximately 100,000 valid weekly reports of fraudsters messaging Facebook and Instagram users.
Meta's own disclosures run alongside. At the Global Anti-Scam Summit in Washington on December 3, 2025, the company reported removing more than 134 million scam advertisements during 2025 and disrupting nearly 12 million accounts across Facebook, Instagram, and WhatsApp in the first half of 2025 associated with criminal scam centres. A joint law enforcement operation with the FBI, the Department of Justice Scam Center Strike Force, and the Royal Thai Police Anti-Cyber Scam Center disabled more than 150,000 further accounts.
The economics on the attacker side have moved in the wrong direction. HUMAN Security's Satori threat intelligence team documented a phone-farm scam kit available for 5,000 dollars upfront and 450 dollars a month, against an estimated 27.8 billion dollars in annual romance and pig-butchering scam losses.
Regulators have started writing account security into code. Ofcom's draft scam-ad measures, published in July 2026 against an estimated 200 million pounds in annual UK losses to fraudulent advertising, include measure H3 requiring an account security mechanism on all advertising accounts and measure H4 requiring an account takeover reporting mechanism. The consultation closes on 2 October, with rules expected in 2027.
Consumer-side two-step verification on WhatsApp does not answer any of that directly. It does sit on the same axis: platforms are being pushed, by litigation and by regulators, to raise the cost of holding a stolen identity.
The regulatory frame in Europe
WhatsApp's product cadence in 2026 has run alongside sustained European pressure. The service enabled interoperable third-party messaging with BirdyChat and Haiket on November 14, 2025 under Article 7 obligations. The European Commission issued a Supplementary Statement of Objections on April 15, 2026 in case AT.41034 over Meta's exclusion of rival AI assistants from WhatsApp, then ordered the company on June 9, 2026 to restore free API access for third-party general-purpose assistants under the terms in place before October 15, 2025.
None of that touches account security directly. It shapes the environment in which the announcement was made. Security features that alter authentication flows across the European Economic Area intersect with interoperability obligations, because a third-party client connecting through WhatsApp's server infrastructure inherits whatever credential model the host service defines. The announcement is silent on whether the password upgrade or the multi-passkey capability affects interoperable clients.
What was not published
The gaps in the August 25 post are worth listing, because they determine what can and cannot be assessed.
No rollout dates were given for any of the three changes. No market sequence was published. No distinction was drawn between the European Region and other territories. The caller context feature is specified for Android with no iOS commitment. The passkey figure carries no baseline and no growth period. Migration handling for existing six-digit PINs is not addressed. No security incident, breach, or takeover volume is cited as the motivation.
The post closes with a forward-looking sentence and nothing attached to it: according to WhatsApp, the company will keep building tools that help people stay in control of their accounts.
Timeline
- July 1, 2025 - Meta launches the WhatsApp Business Calling API, folding voice into existing business message threads
- June 16, 2025 - WhatsApp Status advertising is announced globally, using signals from connected Instagram and Facebook accounts
- November 9, 2025 - Reuters-sourced internal documents indicate Meta projected about 10% of 2024 revenue from scam and banned-goods advertising
- November 14, 2025 - WhatsApp enables interoperable third-party messaging in Europe with BirdyChat and Haiket
- December 3, 2025 - Meta reports removing more than 134 million scam advertisements during 2025 at the Global Anti-Scam Summit
- December 22, 2025 - Meta adds a WhatsApp filter to the Ads Library
- March 6, 2026 - Meta's third DMA compliance report confirms WhatsApp Channels and Status advertising for the European Union
- April 15, 2026 - The European Commission issues a Supplementary Statement of Objections in case AT.41034
- April 21, 2026 - The Consumer Federation of America files a class action against Meta over scam advertising
- May 13, 2026 - Google Ads API v24.1 introduces the passkey_enabled field
- May 18, 2026 - Embedded signup v4 sets an October 15, 2026 deprecation deadline for Click-to-WhatsApp onboarding
- June 3, 2026 - Meta Business Agent launches globally across WhatsApp, Messenger, and Instagram
- June 9, 2026 - The European Commission orders Meta to reopen WhatsApp to rival AI assistants
- June 29, 2026 - WhatsApp opens username reservations, removing the phone number requirement for first contact
- July 15, 2026 - Google Ads begins requiring passkeys for sensitive account actions
- July 20, 2026 - Ofcom proposes scam-ad measures including account security and takeover reporting requirements
- July 28, 2026 - WhatsApp adds calling from the browser, call transfer, waiting rooms, and noise suppression
- July 28, 2026 - HUMAN Security publishes the FunFoneFarm report documenting a 5,000 dollar scam-kit entry point
- July 29, 2026 - Marketing API v26.0 expands Ads in WhatsApp Status and adds the wamo_whatsapp_identity_spec requirement
- August 5, 2026 - Google Ads API OAuth 2.0 refresh token generation begins requiring a passkey
- August 25, 2026 - WhatsApp replaces the six-digit two-step verification PIN with a full alphanumeric password, adds caller context on Android, and reports more than one billion passkey setups
Related PPC Land coverage
- WhatsApp drops phone number requirement for new contacts with username feature - Documents the June 2026 username reservation window and the non-searchable directory design.
- WhatsApp brings calling to the browser, no download required - Records the July 2026 calling update and the pattern of releases shipping without rollout schedules.
- WhatsApp introduces ads using Instagram and Facebook data - Covers the June 2025 arrival of Status advertising and the cross-account signals used for targeting.
- Meta's 2026 DMA report reveals WhatsApp ads, a EU200m fine, and a defiant stance on personalized advertising - Sets out the March 2026 compliance filing confirming European advertising plans.
- WhatsApp enables third-party messaging in Europe under DMA compliance - Details the November 2025 interoperability rollout and the encryption conditions imposed on partner services.
- Google Ads will require passkeys for sensitive actions from July 15 - Explains how the same credential model was applied to advertising account administration.
- Meta removes 134 million scam ads in 2025 amid expanding fraud crisis - Reports the December 2025 enforcement figures and the accounts disrupted across WhatsApp.
- Ofcom proposes scam-ad code as UK loses 200m a year to fraud ads - Covers the draft measures that would require account security mechanisms on advertising accounts.
- Meta deploys AI and law enforcement to fight scams across Facebook, WhatsApp - Documents the joint disruption operations and the advertiser verification expansion.
- Meta Business Agent brings AI customer service to WhatsApp globally - Describes the June 2026 rollout of conversational agents across Meta's messaging platforms.
- EU forces Meta to reopen WhatsApp to rival AI assistants - Covers the June 2026 interim measures decision in case AT.41034.
- Metas Messenger gets a cryptographic shield nobody asked about - but everyone needed - Examines how Meta reconciles security scanning with end-to-end encryption on a sibling product.
Summary
Who: WhatsApp, the messaging service owned by Meta Platforms, publishing through the Meta Newsroom without a named author. The changes affect consumer account holders, and indirectly the advertisers, agencies, and business messaging operators building on WhatsApp Status advertising, Click-to-WhatsApp campaigns, and the WhatsApp Business Platform.
What: Three account security changes. Two-step verification moves from a six-digit numeric PIN to a full alphanumeric password supporting special characters. Android users receive additional context on calls from numbers not in their contacts, specifically whether the number originates in another country and whether groups are shared. Accounts can hold more than one passkey, useful for people operating both Android and iOS devices, and the company reported that more than one billion people have set up a passkey.
When: August 25, 2026. No rollout dates, market sequences, or migration deadlines were published for any of the three changes.
Where: The Meta Newsroom, filed under the Data and Privacy, Product News, and WhatsApp categories. The caller context feature is specified for Android only. Geographic availability is not stated for any change, and no distinction is drawn between the European Economic Area and other territories.
Why: According to WhatsApp, account security work continues alongside default end-to-end encryption because conversations belong to their participants, and scammers rely on urgency that additional caller context is intended to interrupt. The commercial backdrop is a platform that has been converted into an advertising surface since June 2025, an antitrust remedy in Europe, and a documented fraud economy in which account takeover has become an enforcement subject for regulators in the UK and litigation in the United States.
Discussion